Fortinet

Fortiweb

111 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.01%
  • Veröffentlicht 18.11.2025 17:01:19
  • Zuletzt bearbeitet 20.11.2025 14:36:53

A use of hard-coded credentials vulnerability in Fortinet FortiWeb 7.6.0, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow an authenticated attacker with shell access to the device to connect to redis service ...

Warnung Medienbericht
  • EPSS 48.61%
  • Veröffentlicht 18.11.2025 17:01:13
  • Zuletzt bearbeitet 21.11.2025 18:27:43

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 t...

Warnung Exploit
  • EPSS 87.76%
  • Veröffentlicht 14.11.2025 15:50:52
  • Zuletzt bearbeitet 21.11.2025 18:27:33

A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an attacker to execute administrative...

  • EPSS 0.02%
  • Veröffentlicht 14.10.2025 15:23:03
  • Zuletzt bearbeitet 15.10.2025 17:36:57

A insertion of sensitive information into sent data in Fortinet FortiManager Cloud 7.4.1 through 7.4.3, FortiVoice 7.0.0 through 7.0.4, 6.4.0 through 6.4.9, 6.0.7 through 6.0.12, FortiMail 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.9...

  • EPSS 0.08%
  • Veröffentlicht 09.09.2025 13:50:41
  • Zuletzt bearbeitet 10.09.2025 15:14:32

A Relative Path Traversal vulnerability [CWE-23] in FortiWeb 7.6.0 through 7.6.4, 7.4.0 through 7.4.8, 7.2.0 through 7.2.11, 7.0.2 through 7.0.11 may allow an authenticated attacker to perform an arbitrary file read on the underlying system via craft...

  • EPSS 0.05%
  • Veröffentlicht 12.08.2025 19:00:05
  • Zuletzt bearbeitet 15.08.2025 12:25:37

A improper neutralization of special elements used in an os command ('os command injection') vulnerability [CWE-78] in Fortinet FortiWeb CLI version 7.6.0 through 7.6.3 and before 7.4.8 allows a privileged attacker to execute arbitrary code or comman...

  • EPSS 0.04%
  • Veröffentlicht 12.08.2025 18:59:49
  • Zuletzt bearbeitet 14.08.2025 01:21:25

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiWeb version 7.6.0 through 7.6.3, 7.4.0 through 7.4.7, 7.2.0 through 7.2.10 and before 7.0.10 allows an authenticated...

Medienbericht Exploit
  • EPSS 0.5%
  • Veröffentlicht 12.08.2025 18:59:25
  • Zuletzt bearbeitet 15.08.2025 12:26:38

A improper handling of parameters in Fortinet FortiWeb versions 7.6.3 and below, versions 7.4.7 and below, versions 7.2.10 and below, and 7.0.10 and below may allow an unauthenticated remote attacker with non-public information pertaining to the devi...

  • EPSS 0.02%
  • Veröffentlicht 12.08.2025 18:59:16
  • Zuletzt bearbeitet 14.08.2025 01:21:55

A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiWeb CLI version 7.6.0 through 7.6.3 and before 7.4.8 allows a privileged attacker to execute arbitrary code or commands via crafted CLI commands

Warnung
  • EPSS 64.21%
  • Veröffentlicht 17.07.2025 15:10:04
  • Zuletzt bearbeitet 24.10.2025 12:53:24

An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] in Fortinet FortiWeb version 7.6.0 through 7.6.3, 7.4.0 through 7.4.7, 7.2.0 through 7.2.10 and below 7.0.10 allows an unauthenticated atta...